Centralreach · Holmdel, NJCompliance Program Manager at Centralreach — Holmdel, NJ
Full job description
CentralReach is a leading provider of autism and IDD care software for Applied Behavior Analysis (ABA), multidisciplinary therapy, and special education. Trusted by more than 200,000 users, we enable therapy providers, educators, and employers to scale the way they deliver ABA and related therapies with innovative technology, market-leading industry expertise, and world-class customer satisfaction.
The Compliance Program Manager will own and drive CentralReach’s overall compliance program, working directly with the Chief Compliance Officer and Chief Information Security Officer. Beyond day-to-day maintenance and special projects, this role brings program ownership: translating regulatory and security standards into action plans, building KPIs and reporting cadences for leadership, developing metrics, monitoring, and incident response capabilities in partnership with Information Security and Infrastructure teams, and continually evolving the program’s processes and tooling.
Key Accountabilities:
- Lead and Manage Third-Party and Internal Audits
- SOC 2 Type 2
- HIPAA Attestation
- Privacy Audit
- Security Audits
- Compliance Program Strategy & Implementation
- Translate requirements from regulatory and security frameworks (e.g., NIST 800-53, SOC 2, HIPAA) into concrete action items for cross-functional teams
- Track progress and communicate compliance rollout status with the teams doing the work
- Program Reporting & Communication
- Develop KPIs and dashboards to measure compliance program maturity, and report on them regularly to the Chief Compliance Officer and leadership
- Partner with Information Security and IT leadership to continually evolve the compliance program
- Metrics, Monitoring & Incident Response
- Partner with Security and Infrastructure teams to support automated identification, alerting, and response for compliance-relevant risks and incidents
- Maintain the compliance/security Incident Response Plan
- Support on-call and escalation planning for compliance and security incidents
- Compliance Process Development & Tooling
- Create, implement, and automate recurring compliance processes, such as account and access reviews and employee onboarding/offboarding checks
- Identify and evaluate GRC (governance, risk, and compliance) and compliance management tools to support the program
- Projects
- Build out the compliance program KPI framework and reporting cadence for leadership
- Manage Security and Compliance policy updates
Required skills
- communication
- cross-functional
- hipaa